| Category | Package | Started | Completed | Duration | Options | Log |
|---|---|---|---|---|---|---|
| FILE | doc | 2026-04-13 09:01:56 | 2026-04-13 09:05:06 | 190 seconds | Show Options | Show Log |
procdump=1
amsidump=1
2025-12-02 01:31:18,812 [root] INFO: Date set to: 20260413T02:01:54, timeout set to: 150
2026-04-13 03:01:54,015 [root] DEBUG: Starting analyzer from: C:\tmpn7j73yx1
2026-04-13 03:01:54,015 [root] DEBUG: Storing results at: C:\YyIOzAeWhs
2026-04-13 03:01:54,015 [root] DEBUG: Pipe server name: \\.\PIPE\zXIBuEqr
2026-04-13 03:01:54,015 [root] DEBUG: Python path: C:\olddocs
2026-04-13 03:01:54,015 [root] INFO: Analysis package "doc" has been specified
2026-04-13 03:01:54,015 [root] DEBUG: Importing analysis package "doc"...
2026-04-13 03:01:54,031 [root] DEBUG: Initializing analysis package "doc"...
2026-04-13 03:01:54,031 [root] INFO: Analyzer: Package modules.packages.doc does not specify a DLL option
2026-04-13 03:01:54,031 [root] INFO: Analyzer: Package modules.packages.doc does not specify a DLL_64 option
2026-04-13 03:01:54,031 [root] INFO: Analyzer: Package modules.packages.doc does not specify a loader option
2026-04-13 03:01:54,031 [root] INFO: Analyzer: Package modules.packages.doc does not specify a loader_64 option
2026-04-13 03:01:54,062 [root] DEBUG: Importing auxiliary module "modules.auxiliary.browser"...
2026-04-13 03:01:54,062 [root] DEBUG: Importing auxiliary module "modules.auxiliary.curtain"...
2026-04-13 03:01:54,062 [root] DEBUG: Importing auxiliary module "modules.auxiliary.default_apps"...
2026-04-13 03:01:54,078 [root] DEBUG: Importing auxiliary module "modules.auxiliary.digisig"...
2026-04-13 03:01:54,093 [root] DEBUG: Importing auxiliary module "modules.auxiliary.disguise"...
2026-04-13 03:01:54,093 [root] DEBUG: Importing auxiliary module "modules.auxiliary.evtx"...
2026-04-13 03:01:54,109 [root] DEBUG: Importing auxiliary module "modules.auxiliary.fiddler"...
2026-04-13 03:01:54,109 [root] DEBUG: Importing auxiliary module "modules.auxiliary.human"...
2026-04-13 03:01:54,125 [root] DEBUG: Importing auxiliary module "modules.auxiliary.screenshots"...
2026-04-13 03:01:54,125 [lib.api.screenshot] DEBUG: Importing 'PIL.ImageChops'
2026-04-13 03:01:54,234 [lib.api.screenshot] DEBUG: Importing 'PIL.ImageGrab'
2026-04-13 03:01:54,234 [lib.api.screenshot] DEBUG: Importing 'PIL.ImageDraw'
2026-04-13 03:01:54,249 [root] DEBUG: Importing auxiliary module "modules.auxiliary.sysmon"...
2026-04-13 03:01:54,249 [root] DEBUG: Importing auxiliary module "modules.auxiliary.tlsdump"...
2026-04-13 03:01:54,249 [root] DEBUG: Importing auxiliary module "modules.auxiliary.usage"...
2026-04-13 03:01:54,249 [root] DEBUG: Initializing auxiliary module "Browser"...
2026-04-13 03:01:54,249 [root] DEBUG: Started auxiliary module Browser
2026-04-13 03:01:54,249 [root] DEBUG: Initializing auxiliary module "Curtain"...
2026-04-13 03:01:54,249 [root] DEBUG: Started auxiliary module Curtain
2026-04-13 03:01:54,249 [root] DEBUG: Initializing auxiliary module "DefaultApps"...
2026-04-13 03:01:54,296 [modules.auxiliary.default_apps] DEBUG: Getting current user SID using WinAPI
2026-04-13 03:01:54,296 [root] DEBUG: Started auxiliary module DefaultApps
2026-04-13 03:01:54,296 [root] DEBUG: Initializing auxiliary module "DigiSig"...
2026-04-13 03:01:54,296 [modules.auxiliary.digisig] INFO: signtool.exe was not found in bin/
2026-04-13 03:01:54,296 [modules.auxiliary.digisig] INFO: doc
2026-04-13 03:01:54,296 [modules.auxiliary.digisig] INFO: Skipping authenticode validation, unsupported analyzer package
2026-04-13 03:01:54,296 [root] DEBUG: Started auxiliary module DigiSig
2026-04-13 03:01:54,296 [root] DEBUG: Initializing auxiliary module "Disguise"...
2026-04-13 03:01:54,531 [modules.auxiliary.disguise] INFO: Setting NoRecentDocsHistory
2026-04-13 03:01:54,546 [root] WARNING: Cannot execute auxiliary module Disguise: [WinError 2] The system cannot find the file specified
2026-04-13 03:01:54,546 [root] DEBUG: Initializing auxiliary module "Evtx"...
2026-04-13 03:01:54,546 [modules.auxiliary.evtx] INFO: Loading audit policy C:\tmpn7j73yx1\bin\auditpol.csv
2026-04-13 03:01:54,734 [modules.auxiliary.evtx] INFO: Wiping logs: Application, HardwareEvents, Internet Explorer, Key Management Service, OAlerts, Security, Setup, System, Windows PowerShell
2026-04-13 03:01:55,546 [root] DEBUG: Started auxiliary module Evtx
2026-04-13 03:01:55,546 [root] DEBUG: Initializing auxiliary module "Fiddler"...
2026-04-13 03:01:55,546 [modules.auxiliary.fiddler] INFO: fiddler package: doc
2026-04-13 03:01:55,546 [root] DEBUG: Started auxiliary module Fiddler
2026-04-13 03:01:55,546 [root] DEBUG: Initializing auxiliary module "Human"...
2026-04-13 03:01:55,546 [root] DEBUG: Started auxiliary module Human
2026-04-13 03:01:55,546 [root] DEBUG: Initializing auxiliary module "Screenshots"...
2026-04-13 03:01:55,546 [root] DEBUG: Started auxiliary module Screenshots
2026-04-13 03:01:55,546 [root] DEBUG: Initializing auxiliary module "Sysmon"...
2026-04-13 03:01:55,546 [modules.auxiliary.sysmon] INFO: Seeing if we need to update sysmon config
2026-04-13 03:01:55,546 [root] DEBUG: Started auxiliary module Sysmon
2026-04-13 03:01:55,546 [root] DEBUG: Initializing auxiliary module "TLSDumpMasterSecrets"...
2026-04-13 03:01:55,546 [modules.auxiliary.sysmon] INFO: Found Sysmon Executable
2026-04-13 03:01:55,546 [modules.auxiliary.sysmon] INFO: Found Sysmon config
2026-04-13 03:01:55,546 [modules.auxiliary.tlsdump] INFO: lsass.exe found, pid 560
2026-04-13 03:01:55,562 [lib.api.process] INFO: Monitor config for process 560: C:\tmpn7j73yx1\dll\560.ini
2026-04-13 03:01:57,671 [modules.auxiliary.sysmon] INFO: Clearing existing sysmon logs
2026-04-13 03:01:58,562 [lib.api.process] INFO: Option 'procdump' with value '1' sent to monitor
2026-04-13 03:01:58,562 [lib.api.process] INFO: Option 'amsidump' with value '1' sent to monitor
2026-04-13 03:01:58,562 [lib.api.process] INFO: Option 'disable_hook_content' with value '4' sent to monitor
2026-04-13 03:01:58,562 [lib.api.process] INFO: Option 'office' with value '1' sent to monitor
2026-04-13 03:01:58,562 [lib.api.process] INFO: Option 'yarascan' with value '0' sent to monitor
2026-04-13 03:01:58,562 [lib.api.process] INFO: Option 'no-iat' with value '1' sent to monitor
2026-04-13 03:01:58,562 [lib.api.process] INFO: Option 'tlsdump' with value '1' sent to monitor
2026-04-13 03:01:58,562 [lib.api.process] INFO: 64-bit DLL to inject is C:\tmpn7j73yx1\dll\RmgRSYv.dll, loader C:\tmpn7j73yx1\bin\ZFJdUEZo.exe
2026-04-13 03:01:58,578 [root] DEBUG: Loader: IAT patching disabled.
2026-04-13 03:01:58,578 [root] DEBUG: Loader: Injecting process 560 with C:\tmpn7j73yx1\dll\RmgRSYv.dll.
2026-04-13 03:01:58,640 [root] DEBUG: 560: Python path set to 'C:\olddocs'.
2026-04-13 03:01:58,640 [root] DEBUG: 560: Disabling sleep skipping.
2026-04-13 03:01:58,640 [root] DEBUG: 560: Process dumps enabled.
2026-04-13 03:01:58,640 [root] DEBUG: 560: AMSI dumping enabled.
2026-04-13 03:01:58,640 [root] DEBUG: 560: Monitor config - unrecognised key office.
2026-04-13 03:01:58,640 [root] DEBUG: 560: In-monitor YARA scans disabled.
2026-04-13 03:01:58,640 [root] DEBUG: 560: TLS secret dump mode enabled.
2026-04-13 03:01:58,640 [root] DEBUG: 560: Monitor initialised: 64-bit capemon loaded in process 560 at 0x000007FEEDC00000, thread 1956, image base 0x00000000FF510000, stack from 0x00000000021E3000-0x00000000021F0000
2026-04-13 03:01:58,640 [root] DEBUG: 560: Commandline: C:\Windows\system32\lsass.exe
2026-04-13 03:01:58,656 [root] DEBUG: 560: Hooked 5 out of 5 functions
2026-04-13 03:01:58,656 [root] DEBUG: InjectDllViaThread: Successfully injected Dll into process via RtlCreateUserThread.
2026-04-13 03:01:58,656 [root] DEBUG: Successfully injected DLL C:\tmpn7j73yx1\dll\RmgRSYv.dll.
2026-04-13 03:01:58,656 [lib.api.process] INFO: Injected into suspended 64-bit process with pid 560
2026-04-13 03:01:58,656 [root] DEBUG: Started auxiliary module TLSDumpMasterSecrets
2026-04-13 03:01:58,656 [root] DEBUG: Initializing auxiliary module "Usage"...
2026-04-13 03:01:58,656 [root] DEBUG: Started auxiliary module Usage
2026-04-13 03:02:01,296 [root] INFO: Restarting WMI Service
2026-04-13 03:02:07,687 [modules.auxiliary.sysmon] INFO: Dumping sysmon logs
2026-04-13 03:02:10,390 [lib.api.process] INFO: Successfully executed process from path "C:\Program Files (x86)\Microsoft Office\Office15\WINWORD.EXE" with arguments ""C:\Users\pgabriel\AppData\Local\Temp\Invoice.docx" /q" with pid 696
2026-04-13 03:02:10,390 [lib.api.process] INFO: Monitor config for process 696: C:\tmpn7j73yx1\dll\696.ini
2026-04-13 03:02:10,390 [lib.api.process] INFO: Option 'procdump' with value '1' sent to monitor
2026-04-13 03:02:10,390 [lib.api.process] INFO: Option 'amsidump' with value '1' sent to monitor
2026-04-13 03:02:10,390 [lib.api.process] INFO: Option 'disable_hook_content' with value '4' sent to monitor
2026-04-13 03:02:10,390 [lib.api.process] INFO: Option 'office' with value '1' sent to monitor
2026-04-13 03:02:10,390 [lib.api.process] INFO: Option 'yarascan' with value '0' sent to monitor
2026-04-13 03:02:10,390 [lib.api.process] INFO: Option 'no-iat' with value '1' sent to monitor
2026-04-13 03:02:10,390 [lib.api.process] INFO: 32-bit DLL to inject is C:\tmpn7j73yx1\dll\tmABKvY.dll, loader C:\tmpn7j73yx1\bin\fZRrEjY.exe
2026-04-13 03:02:10,406 [root] DEBUG: Loader: IAT patching disabled.
2026-04-13 03:02:10,421 [root] DEBUG: Loader: Injecting process 696 (thread 2596) with C:\tmpn7j73yx1\dll\tmABKvY.dll.
2026-04-13 03:02:10,421 [root] DEBUG: InjectDllViaQueuedAPC: APC injection queued.
2026-04-13 03:02:10,421 [root] DEBUG: Successfully injected DLL C:\tmpn7j73yx1\dll\tmABKvY.dll.
2026-04-13 03:02:10,421 [lib.api.process] INFO: Injected into suspended 32-bit process with pid 696
2026-04-13 03:02:10,546 [modules.auxiliary.evtx] INFO: Collecting logs: Application, HardwareEvents, Internet Explorer, Key Management Service, OAlerts, Security, Setup, System, Windows PowerShell
2026-04-13 03:02:10,843 [lib.common.results] INFO: File 1776074530765625000.HardwareEvents.evtx.gz size is 250, Max size: 100000000
2026-04-13 03:02:10,859 [lib.common.results] INFO: File 1776074530765625000.Application.evtx.gz size is 6956, Max size: 100000000
2026-04-13 03:02:10,859 [lib.common.results] INFO: File 1776074530765625000.InternetExplorer.evtx.gz size is 250, Max size: 100000000
2026-04-13 03:02:10,859 [lib.common.results] INFO: File 1776074530765625000.KeyManagementService.evtx.gz size is 4650, Max size: 100000000
2026-04-13 03:02:10,937 [lib.common.results] INFO: File 1776074530843750000.Setup.evtx.gz size is 241, Max size: 100000000
2026-04-13 03:02:10,937 [lib.common.results] INFO: File 1776074530843750000.OAlerts.evtx.gz size is 244, Max size: 100000000
2026-04-13 03:02:10,937 [lib.common.results] INFO: File 1776074530843750000.System.evtx.gz size is 8667, Max size: 100000000
2026-04-13 03:02:10,968 [lib.common.results] INFO: File 1776074530843750000.Security.evtx.gz size is 15414, Max size: 100000000
2026-04-13 03:02:10,984 [lib.common.results] INFO: File 1776074530937500000.WindowsPowerShell.evtx.gz size is 2058, Max size: 100000000
2026-04-13 03:02:12,421 [lib.api.process] INFO: Successfully resumed process with pid 696
2026-04-13 03:02:12,593 [root] DEBUG: 696: Python path set to 'C:\olddocs'.
2026-04-13 03:02:12,593 [root] DEBUG: 696: Disabling sleep skipping.
2026-04-13 03:02:12,593 [root] DEBUG: 696: Process dumps enabled.
2026-04-13 03:02:12,593 [root] DEBUG: 696: AMSI dumping enabled.
2026-04-13 03:02:12,593 [root] DEBUG: 696: Monitor config - unrecognised key office.
2026-04-13 03:02:12,593 [root] DEBUG: 696: In-monitor YARA scans disabled.
2026-04-13 03:02:12,593 [root] DEBUG: 696: Dropped file limit defaulting to 100.
2026-04-13 03:02:12,609 [root] DEBUG: 696: Microsoft Office settings enabled.
2026-04-13 03:02:12,609 [root] DEBUG: 696: Monitor initialised: 32-bit capemon loaded in process 696 at 0x72940000, thread 2596, image base 0x900000, stack from 0x453000-0x460000
2026-04-13 03:02:12,609 [root] DEBUG: 696: Commandline: "C:\Program Files (x86)\Microsoft Office\Office15\WINWORD.EXE" "C:\Users\pgabriel\AppData\Local\Temp\Invoice.docx" /q
2026-04-13 03:02:12,640 [root] DEBUG: 696: Hooked 456 out of 456 functions
2026-04-13 03:02:12,656 [root] INFO: Loaded monitor into process with pid 696
2026-04-13 03:02:12,796 [modules.auxiliary.sysmon] INFO: Uploading sysmon/1776074532.796875.sysmon.evtx.gz to host
2026-04-13 03:02:12,796 [lib.common.results] INFO: File C:\Sysmon.evtx.gz size is 8919, Max size: 100000000
2026-04-13 03:02:12,906 [root] DEBUG: 696: DLL loaded at 0x71480000: C:\Program Files (x86)\Microsoft Office\Office15\wwlib (0x14bc000 bytes).
2026-04-13 03:02:12,937 [root] DEBUG: 696: DLL loaded at 0x73E30000: C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus (0x190000 bytes).
2026-04-13 03:02:13,093 [root] DEBUG: 696: DLL loaded at 0x706D0000: C:\Program Files (x86)\Microsoft Office\Office15\oart (0xda8000 bytes).
2026-04-13 03:02:13,109 [root] DEBUG: 696: DLL loaded at 0x74280000: C:\Windows\system32\MSVCP100 (0x69000 bytes).
2026-04-13 03:02:13,156 [root] DEBUG: 696: DLL loaded at 0x70380000: C:\Windows\system32\d2d1 (0x347000 bytes).
2026-04-13 03:02:13,171 [root] DEBUG: 696: DLL loaded at 0x6EA90000: C:\Program Files (x86)\Common Files\Microsoft Shared\Office15\mso (0x18e4000 bytes).
2026-04-13 03:02:13,171 [root] DEBUG: 696: DLL loaded at 0x73440000: C:\Windows\system32\MSIMG32 (0x5000 bytes).
2026-04-13 03:02:13,187 [root] DEBUG: 696: DLL loaded at 0x73510000: C:\Windows\system32\uxtheme (0x80000 bytes).
2026-04-13 03:02:13,203 [root] DEBUG: 696: DLL loaded at 0x73750000: C:\Windows\system32\WTSAPI32 (0xd000 bytes).
2026-04-13 03:02:13,203 [root] DEBUG: 696: DLL loaded at 0x74250000: C:\Windows\system32\WINSTA (0x29000 bytes).
2026-04-13 03:02:13,203 [root] DEBUG: 696: DLL loaded at 0x73DE0000: C:\Windows\system32\dxgi (0x4c000 bytes).
2026-04-13 03:02:13,203 [root] DEBUG: 696: DLL loaded at 0x73760000: C:\Windows\system32\VERSION (0x9000 bytes).
2026-04-13 03:02:13,203 [root] DEBUG: 696: DLL loaded at 0x73DC0000: C:\Windows\system32\dwmapi (0x13000 bytes).
2026-04-13 03:02:13,218 [root] DEBUG: 696: DLL loaded at 0x757C0000: C:\Windows\syswow64\setupapi (0x19d000 bytes).
2026-04-13 03:02:13,218 [root] DEBUG: 696: DLL loaded at 0x75B40000: C:\Windows\syswow64\CFGMGR32 (0x27000 bytes).
2026-04-13 03:02:13,218 [root] DEBUG: 696: DLL loaded at 0x75B20000: C:\Windows\syswow64\DEVOBJ (0x12000 bytes).
2026-04-13 03:02:13,218 [root] DEBUG: 696: DLL loaded at 0x75730000: C:\Windows\syswow64\WINTRUST (0x2f000 bytes).
2026-04-13 03:02:13,218 [root] DEBUG: 696: DLL loaded at 0x757C0000: C:\Windows\syswow64\setupapi (0x19d000 bytes).
2026-04-13 03:02:13,234 [root] DEBUG: 696: DLL loaded at 0x75B40000: C:\Windows\syswow64\CFGMGR32 (0x27000 bytes).
2026-04-13 03:02:13,234 [root] DEBUG: 696: DLL loaded at 0x75B20000: C:\Windows\syswow64\DEVOBJ (0x12000 bytes).
2026-04-13 03:02:13,249 [root] DEBUG: 696: DLL loaded at 0x6E850000: C:\Windows\system32\msi (0x240000 bytes).
2026-04-13 03:02:13,468 [root] DEBUG: 696: DLL loaded at 0x6E170000: C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE15\MSPTLS (0x116000 bytes).
2026-04-13 03:02:13,484 [root] DEBUG: 696: DLL loaded at 0x760F0000: C:\Windows\syswow64\SHELL32 (0xc4a000 bytes).
2026-04-13 03:02:13,500 [root] DEBUG: 696: DLL loaded at 0x753B0000: C:\Windows\syswow64\profapi (0xb000 bytes).
2026-04-13 03:02:13,500 [root] DEBUG: 696: DLL loaded at 0x73590000: C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\Comctl32 (0x19e000 bytes).
2026-04-13 03:02:13,593 [root] DEBUG: 696: DLL loaded at 0x73D90000: C:\Windows\system32\d3d10_1 (0x2c000 bytes).
2026-04-13 03:02:13,593 [root] DEBUG: 696: DLL loaded at 0x73D40000: C:\Windows\system32\d3d10_1core (0x41000 bytes).
2026-04-13 03:02:13,593 [root] DEBUG: 696: DLL loaded at 0x6DC70000: C:\Windows\system32\d3d11 (0x175000 bytes).
2026-04-13 03:02:13,609 [root] DEBUG: 696: DLL loaded at 0x6DA80000: C:\Windows\system32\D3D10Warp (0x1e9000 bytes).
2026-04-13 03:02:13,609 [root] DEBUG: 696: DLL loaded at 0x757C0000: C:\Windows\syswow64\setupapi (0x19d000 bytes).
2026-04-13 03:02:13,609 [root] DEBUG: 696: DLL loaded at 0x75B40000: C:\Windows\syswow64\CFGMGR32 (0x27000 bytes).
2026-04-13 03:02:13,609 [root] DEBUG: 696: DLL loaded at 0x75B20000: C:\Windows\syswow64\DEVOBJ (0x12000 bytes).
2026-04-13 03:02:13,625 [root] DEBUG: 696: DLL loaded at 0x757C0000: C:\Windows\syswow64\setupapi (0x19d000 bytes).
2026-04-13 03:02:13,625 [root] DEBUG: 696: DLL loaded at 0x75B40000: C:\Windows\syswow64\CFGMGR32 (0x27000 bytes).
2026-04-13 03:02:13,640 [root] DEBUG: 696: DLL loaded at 0x757C0000: C:\Windows\syswow64\setupapi (0x19d000 bytes).
2026-04-13 03:02:13,640 [root] DEBUG: 696: DLL loaded at 0x75B40000: C:\Windows\syswow64\CFGMGR32 (0x27000 bytes).
2026-04-13 03:02:13,640 [root] DEBUG: 696: DLL loaded at 0x75B20000: C:\Windows\syswow64\DEVOBJ (0x12000 bytes).
2026-04-13 03:02:13,656 [root] DEBUG: 696: DLL loaded at 0x757C0000: C:\Windows\syswow64\setupapi (0x19d000 bytes).
2026-04-13 03:02:13,656 [root] DEBUG: 696: DLL loaded at 0x75B40000: C:\Windows\syswow64\CFGMGR32 (0x27000 bytes).
2026-04-13 03:02:13,656 [root] DEBUG: 696: DLL loaded at 0x75B20000: C:\Windows\syswow64\DEVOBJ (0x12000 bytes).
2026-04-13 03:02:13,765 [root] DEBUG: 696: DLL loaded at 0x6D950000: C:\Windows\system32\WindowsCodecs (0x130000 bytes).
2026-04-13 03:02:13,765 [root] DEBUG: 696: DLL loaded at 0x757C0000: C:\Windows\syswow64\setupapi (0x19d000 bytes).
2026-04-13 03:02:13,765 [root] DEBUG: 696: DLL loaded at 0x75B40000: C:\Windows\syswow64\CFGMGR32 (0x27000 bytes).
2026-04-13 03:02:13,765 [root] DEBUG: 696: DLL loaded at 0x75B20000: C:\Windows\syswow64\DEVOBJ (0x12000 bytes).
2026-04-13 03:02:13,781 [root] DEBUG: 696: DLL loaded at 0x757C0000: C:\Windows\syswow64\setupapi (0x19d000 bytes).
2026-04-13 03:02:13,781 [root] DEBUG: 696: DLL loaded at 0x75B40000: C:\Windows\syswow64\CFGMGR32 (0x27000 bytes).
2026-04-13 03:02:13,781 [root] DEBUG: 696: DLL loaded at 0x75B20000: C:\Windows\syswow64\DEVOBJ (0x12000 bytes).
2026-04-13 03:02:13,796 [root] DEBUG: 696: DLL loaded at 0x6D810000: C:\Windows\system32\DWrite (0x135000 bytes).
2026-04-13 03:02:13,812 [root] DEBUG: 696: DLL loaded at 0x731B0000: C:\Windows\system32\mscoree (0x4a000 bytes).
2026-04-13 03:02:13,812 [root] DEBUG: 696: DLL loaded at 0x6D780000: C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscoreei (0x8d000 bytes).
2026-04-13 03:02:13,812 [root] DEBUG: 696: DLL loaded at 0x6D6C0000: C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE15\adal (0xb5000 bytes).
2026-04-13 03:02:13,828 [root] DEBUG: 696: DLL loaded at 0x6D660000: C:\Windows\system32\WINHTTP (0x58000 bytes).
2026-04-13 03:02:13,843 [root] DEBUG: 696: DLL loaded at 0x73160000: C:\Windows\system32\webio (0x50000 bytes).
2026-04-13 03:02:13,843 [root] DEBUG: 696: DLL loaded at 0x75C70000: C:\Windows\syswow64\WININET (0x1e4000 bytes).
2026-04-13 03:02:13,843 [root] DEBUG: 696: DLL loaded at 0x75F70000: C:\Windows\syswow64\api-ms-win-downlevel-user32-l1-1-0 (0x4000 bytes).
2026-04-13 03:02:13,843 [root] DEBUG: 696: DLL loaded at 0x75720000: C:\Windows\syswow64\api-ms-win-downlevel-shlwapi-l1-1-0 (0x4000 bytes).
2026-04-13 03:02:13,843 [root] DEBUG: 696: DLL loaded at 0x75A20000: C:\Windows\syswow64\api-ms-win-downlevel-version-l1-1-0 (0x4000 bytes).
2026-04-13 03:02:13,843 [root] DEBUG: 696: DLL loaded at 0x752B0000: C:\Windows\syswow64\api-ms-win-downlevel-normaliz-l1-1-0 (0x3000 bytes).
2026-04-13 03:02:13,843 [root] DEBUG: 696: DLL loaded at 0x77020000: C:\Windows\syswow64\normaliz (0x3000 bytes).
2026-04-13 03:02:13,843 [root] DEBUG: 696: DLL loaded at 0x753C0000: C:\Windows\syswow64\iertutil (0x232000 bytes).
2026-04-13 03:02:13,843 [root] DEBUG: 696: DLL loaded at 0x77300000: C:\Windows\syswow64\api-ms-win-downlevel-advapi32-l1-1-0 (0x5000 bytes).
2026-04-13 03:02:13,843 [root] DEBUG: 696: DLL loaded at 0x77310000: C:\Windows\syswow64\USERENV (0x17000 bytes).
2026-04-13 03:02:13,859 [root] DEBUG: 696: DLL loaded at 0x74750000: C:\Windows\system32\Secur32 (0x8000 bytes).
2026-04-13 03:02:13,937 [root] DEBUG: 696: DLL loaded at 0x752D0000: C:\Windows\syswow64\CLBCatQ (0x83000 bytes).
2026-04-13 03:02:13,937 [root] DEBUG: 696: DLL loaded at 0x6D600000: C:\Windows\System32\netprofm (0x5a000 bytes).
2026-04-13 03:02:13,937 [root] DEBUG: 696: DLL loaded at 0x74310000: C:\Windows\System32\nlaapi (0x10000 bytes).
2026-04-13 03:02:13,953 [root] DEBUG: 696: DLL loaded at 0x73240000: C:\Windows\system32\CRYPTSP (0x17000 bytes).
2026-04-13 03:02:13,953 [root] DEBUG: 696: DLL loaded at 0x73200000: C:\Windows\system32\rsaenh (0x3b000 bytes).
2026-04-13 03:02:13,968 [root] DEBUG: 696: DLL loaded at 0x73C10000: C:\Windows\system32\RpcRtRemote (0xe000 bytes).
2026-04-13 03:02:13,968 [root] DEBUG: 696: DLL loaded at 0x74240000: C:\Windows\System32\npmproxy (0x8000 bytes).
2026-04-13 03:02:14,203 [root] DEBUG: 696: DLL loaded at 0x6D470000: C:\Program Files (x86)\Common Files\Microsoft Shared\Office15\riched20 (0x18e000 bytes).
2026-04-13 03:02:14,203 [root] DEBUG: 696: DLL loaded at 0x73D10000: C:\Program Files (x86)\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\osppc (0x2d000 bytes).
2026-04-13 03:02:14,218 [root] DEBUG: 696: DLL loaded at 0x68720000: C:\Windows\system32\WINSPOOL.DRV (0x51000 bytes).
2026-04-13 03:02:14,265 [root] DEBUG: 696: DLL loaded at 0x757C0000: C:\Windows\syswow64\SETUPAPI (0x19d000 bytes).
2026-04-13 03:02:14,265 [root] DEBUG: 696: DLL loaded at 0x75B40000: C:\Windows\syswow64\CFGMGR32 (0x27000 bytes).
2026-04-13 03:02:14,265 [root] DEBUG: 696: DLL loaded at 0x75B20000: C:\Windows\syswow64\DEVOBJ (0x12000 bytes).
2026-04-13 03:02:14,265 [root] DEBUG: 696: DLL loaded at 0x68620000: C:\Windows\system32\propsys (0xf5000 bytes).
2026-04-13 03:02:14,265 [root] DEBUG: 696: DLL loaded at 0x73460000: C:\Windows\system32\ntmarta (0x21000 bytes).
2026-04-13 03:02:14,281 [root] DEBUG: 696: DLL loaded at 0x751C0000: C:\Windows\syswow64\WLDAP32 (0x45000 bytes).
2026-04-13 03:02:14,328 [root] INFO: Added new file to list with pid None and path C:\Users\pgabriel\AppData\Roaming\Microsoft\Templates\Normal.dotm
2026-04-13 03:02:14,359 [root] DEBUG: 696: DLL loaded at 0x684C0000: C:\Windows\System32\msxml6 (0x158000 bytes).
2026-04-13 03:02:14,437 [root] DEBUG: 696: DLL loaded at 0x68490000: C:\Windows\system32\XmlLite (0x2f000 bytes).
2026-04-13 03:02:14,578 [root] DEBUG: 696: DLL loaded at 0x770E0000: C:\Windows\SysWOW64\urlmon (0x14a000 bytes).
2026-04-13 03:02:14,578 [root] DEBUG: 696: DLL loaded at 0x772F0000: C:\Windows\syswow64\api-ms-win-downlevel-ole32-l1-1-0 (0x4000 bytes).
2026-04-13 03:02:14,609 [root] DEBUG: 696: DLL loaded at 0x73390000: C:\Windows\system32\api-ms-win-downlevel-advapi32-l2-1-0 (0x4000 bytes).
2026-04-13 03:02:14,625 [root] INFO: Added new file to list with pid None and path C:\Users\pgabriel\AppData\Local\Temp\~$nvoice.docx
2026-04-13 03:02:14,812 [root] DEBUG: 696: DLL loaded at 0x68430000: C:\Windows\system32\SXS (0x5f000 bytes).
2026-04-13 03:02:18,628 [lib.common.results] INFO: File c:\olddocs\1776074533625.saz size is 4606, Max size: 100000000
2026-04-13 03:02:18,644 [modules.auxiliary.fiddler] ERROR: Saz log file not found in guest machine
2026-04-13 03:02:19,074 [root] DEBUG: 696: DLL loaded at 0x68400000: C:\Windows\system32\POWRPROF (0x25000 bytes).
2026-04-13 03:02:26,046 [modules.auxiliary.evtx] INFO: Collecting logs: Application, HardwareEvents, Internet Explorer, Key Management Service, OAlerts, Security, Setup, System, Windows PowerShell
2026-04-13 03:02:26,320 [lib.common.results] INFO: File 1776074546257812500.InternetExplorer.evtx.gz size is 250, Max size: 100000000
2026-04-13 03:02:26,343 [lib.common.results] INFO: File 1776074546257812500.HardwareEvents.evtx.gz size is 250, Max size: 100000000
2026-04-13 03:02:26,343 [lib.common.results] INFO: File 1776074546257812500.KeyManagementService.evtx.gz size is 4650, Max size: 100000000
2026-04-13 03:02:26,343 [lib.common.results] INFO: File 1776074546257812500.Application.evtx.gz size is 6890, Max size: 100000000
2026-04-13 03:02:26,375 [lib.common.results] INFO: File 1776074546320312500.Security.evtx.gz size is 8277, Max size: 100000000
2026-04-13 03:02:26,382 [lib.common.results] INFO: File 1776074546320312500.Setup.evtx.gz size is 241, Max size: 100000000
2026-04-13 03:02:26,390 [lib.common.results] INFO: File 1776074546312500000.OAlerts.evtx.gz size is 244, Max size: 100000000
2026-04-13 03:02:26,398 [lib.common.results] INFO: File 1776074546328125000.System.evtx.gz size is 8402, Max size: 100000000
2026-04-13 03:02:26,421 [lib.common.results] INFO: File 1776074546375000000.WindowsPowerShell.evtx.gz size is 2058, Max size: 100000000
2026-04-13 03:02:27,813 [modules.auxiliary.sysmon] INFO: Dumping sysmon logs
2026-04-13 03:02:32,926 [modules.auxiliary.sysmon] INFO: Uploading sysmon/1776074552.9267578.sysmon.evtx.gz to host
2026-04-13 03:02:32,926 [lib.common.results] INFO: File C:\Sysmon.evtx.gz size is 55843, Max size: 100000000
2026-04-13 03:02:38,753 [modules.auxiliary.fiddler] ERROR: Saz log file not found in guest machine
2026-04-13 03:02:41,458 [modules.auxiliary.evtx] INFO: Collecting logs: Application, HardwareEvents, Internet Explorer, Key Management Service, OAlerts, Security, Setup, System, Windows PowerShell
2026-04-13 03:02:41,693 [lib.common.results] INFO: File 1776074561646484300.HardwareEvents.evtx.gz size is 250, Max size: 100000000
2026-04-13 03:02:41,724 [lib.common.results] INFO: File 1776074561646484300.InternetExplorer.evtx.gz size is 250, Max size: 100000000
2026-04-13 03:02:41,724 [lib.common.results] INFO: File 1776074561646484300.Application.evtx.gz size is 6890, Max size: 100000000
2026-04-13 03:02:41,740 [lib.common.results] INFO: File 1776074561646484300.KeyManagementService.evtx.gz size is 4650, Max size: 100000000
2026-04-13 03:02:41,758 [lib.common.results] INFO: File 1776074561693359300.Setup.evtx.gz size is 241, Max size: 100000000
2026-04-13 03:02:41,761 [lib.common.results] INFO: File 1776074561693359300.OAlerts.evtx.gz size is 244, Max size: 100000000
2026-04-13 03:02:41,764 [lib.common.results] INFO: File 1776074561693359300.Security.evtx.gz size is 8114, Max size: 100000000
2026-04-13 03:02:41,778 [lib.common.results] INFO: File 1776074561708984300.System.evtx.gz size is 8036, Max size: 100000000
2026-04-13 03:02:41,791 [lib.common.results] INFO: File 1776074561756835900.WindowsPowerShell.evtx.gz size is 2058, Max size: 100000000
2026-04-13 03:02:47,951 [modules.auxiliary.sysmon] INFO: Dumping sysmon logs
2026-04-13 03:02:53,040 [modules.auxiliary.sysmon] INFO: Uploading sysmon/1776074573.0400388.sysmon.evtx.gz to host
2026-04-13 03:02:53,040 [lib.common.results] INFO: File C:\Sysmon.evtx.gz size is 7862, Max size: 100000000
2026-04-13 03:02:56,839 [modules.auxiliary.evtx] INFO: Collecting logs: Application, HardwareEvents, Internet Explorer, Key Management Service, OAlerts, Security, Setup, System, Windows PowerShell
2026-04-13 03:02:57,074 [lib.common.results] INFO: File 1776074577019531200.HardwareEvents.evtx.gz size is 250, Max size: 100000000
2026-04-13 03:02:57,082 [lib.common.results] INFO: File 1776074577019531200.InternetExplorer.evtx.gz size is 250, Max size: 100000000
2026-04-13 03:02:57,082 [lib.common.results] INFO: File 1776074577019531200.Application.evtx.gz size is 6890, Max size: 100000000
2026-04-13 03:02:57,089 [lib.common.results] INFO: File 1776074577019531200.KeyManagementService.evtx.gz size is 4650, Max size: 100000000
2026-04-13 03:02:57,136 [lib.common.results] INFO: File 1776074577082031200.Setup.evtx.gz size is 241, Max size: 100000000
2026-04-13 03:02:57,136 [lib.common.results] INFO: File 1776074577074218700.OAlerts.evtx.gz size is 244, Max size: 100000000
2026-04-13 03:02:57,136 [lib.common.results] INFO: File 1776074577082031200.System.evtx.gz size is 8030, Max size: 100000000
2026-04-13 03:02:57,152 [lib.common.results] INFO: File 1776074577082031200.Security.evtx.gz size is 8035, Max size: 100000000
2026-04-13 03:02:57,167 [lib.common.results] INFO: File 1776074577136718700.WindowsPowerShell.evtx.gz size is 2058, Max size: 100000000
2026-04-13 03:02:58,865 [modules.auxiliary.fiddler] ERROR: Saz log file not found in guest machine
2026-04-13 03:03:08,071 [modules.auxiliary.sysmon] INFO: Dumping sysmon logs
2026-04-13 03:03:12,216 [modules.auxiliary.evtx] INFO: Collecting logs: Application, HardwareEvents, Internet Explorer, Key Management Service, OAlerts, Security, Setup, System, Windows PowerShell
2026-04-13 03:03:12,451 [lib.common.results] INFO: File 1776074592404296800.HardwareEvents.evtx.gz size is 250, Max size: 100000000
2026-04-13 03:03:12,466 [lib.common.results] INFO: File 1776074592404296800.InternetExplorer.evtx.gz size is 250, Max size: 100000000
2026-04-13 03:03:12,466 [lib.common.results] INFO: File 1776074592404296800.Application.evtx.gz size is 6956, Max size: 100000000
2026-04-13 03:03:12,466 [lib.common.results] INFO: File 1776074592404296800.KeyManagementService.evtx.gz size is 4650, Max size: 100000000
2026-04-13 03:03:12,513 [lib.common.results] INFO: File 1776074592451171800.OAlerts.evtx.gz size is 244, Max size: 100000000
2026-04-13 03:03:12,513 [lib.common.results] INFO: File 1776074592451171800.Security.evtx.gz size is 8105, Max size: 100000000
2026-04-13 03:03:12,513 [lib.common.results] INFO: File 1776074592451171800.Setup.evtx.gz size is 241, Max size: 100000000
2026-04-13 03:03:12,513 [lib.common.results] INFO: File 1776074592466796800.System.evtx.gz size is 8038, Max size: 100000000
2026-04-13 03:03:12,544 [lib.common.results] INFO: File 1776074592513671800.WindowsPowerShell.evtx.gz size is 2058, Max size: 100000000
2026-04-13 03:03:13,154 [modules.auxiliary.sysmon] INFO: Uploading sysmon/1776074593.1542969.sysmon.evtx.gz to host
2026-04-13 03:03:13,154 [lib.common.results] INFO: File C:\Sysmon.evtx.gz size is 7688, Max size: 100000000
2026-04-13 03:03:18,971 [modules.auxiliary.fiddler] ERROR: Saz log file not found in guest machine
2026-04-13 03:03:27,585 [modules.auxiliary.evtx] INFO: Collecting logs: Application, HardwareEvents, Internet Explorer, Key Management Service, OAlerts, Security, Setup, System, Windows PowerShell
2026-04-13 03:03:27,848 [lib.common.results] INFO: File 1776074607799804600.HardwareEvents.evtx.gz size is 250, Max size: 100000000
2026-04-13 03:03:27,864 [lib.common.results] INFO: File 1776074607800781200.InternetExplorer.evtx.gz size is 250, Max size: 100000000
2026-04-13 03:03:27,864 [lib.common.results] INFO: File 1776074607799804600.Application.evtx.gz size is 6888, Max size: 100000000
2026-04-13 03:03:27,872 [lib.common.results] INFO: File 1776074607811523400.KeyManagementService.evtx.gz size is 4650, Max size: 100000000
2026-04-13 03:03:27,911 [lib.common.results] INFO: File 1776074607856445300.Setup.evtx.gz size is 241, Max size: 100000000
2026-04-13 03:03:27,918 [lib.common.results] INFO: File 1776074607848632800.OAlerts.evtx.gz size is 244, Max size: 100000000
2026-04-13 03:03:27,934 [lib.common.results] INFO: File 1776074607864257800.System.evtx.gz size is 8055, Max size: 100000000
2026-04-13 03:03:27,934 [lib.common.results] INFO: File 1776074607848632800.Security.evtx.gz size is 8045, Max size: 100000000
2026-04-13 03:03:27,950 [lib.common.results] INFO: File 1776074607903320300.WindowsPowerShell.evtx.gz size is 2058, Max size: 100000000
2026-04-13 03:03:28,192 [modules.auxiliary.sysmon] INFO: Dumping sysmon logs
2026-04-13 03:03:33,265 [modules.auxiliary.sysmon] INFO: Uploading sysmon/1776074613.265625.sysmon.evtx.gz to host
2026-04-13 03:03:33,265 [lib.common.results] INFO: File C:\Sysmon.evtx.gz size is 7671, Max size: 100000000
2026-04-13 03:03:39,068 [modules.auxiliary.fiddler] ERROR: Saz log file not found in guest machine
2026-04-13 03:03:42,994 [modules.auxiliary.evtx] INFO: Collecting logs: Application, HardwareEvents, Internet Explorer, Key Management Service, OAlerts, Security, Setup, System, Windows PowerShell
2026-04-13 03:03:43,212 [lib.common.results] INFO: File 1776074623166015600.HardwareEvents.evtx.gz size is 250, Max size: 100000000
2026-04-13 03:03:43,212 [lib.common.results] INFO: File 1776074623166015600.InternetExplorer.evtx.gz size is 250, Max size: 100000000
2026-04-13 03:03:43,228 [lib.common.results] INFO: File 1776074623158203100.Application.evtx.gz size is 6888, Max size: 100000000
2026-04-13 03:03:43,228 [lib.common.results] INFO: File 1776074623166015600.KeyManagementService.evtx.gz size is 4650, Max size: 100000000
2026-04-13 03:03:43,259 [lib.common.results] INFO: File 1776074623212890600.Setup.evtx.gz size is 241, Max size: 100000000
2026-04-13 03:03:43,275 [lib.common.results] INFO: File 1776074623212890600.OAlerts.evtx.gz size is 244, Max size: 100000000
2026-04-13 03:03:43,275 [lib.common.results] INFO: File 1776074623212890600.Security.evtx.gz size is 8146, Max size: 100000000
2026-04-13 03:03:43,291 [lib.common.results] INFO: File 1776074623228515600.System.evtx.gz size is 8073, Max size: 100000000
2026-04-13 03:03:43,306 [lib.common.results] INFO: File 1776074623259765600.WindowsPowerShell.evtx.gz size is 2058, Max size: 100000000
2026-04-13 03:03:48,285 [modules.auxiliary.sysmon] INFO: Dumping sysmon logs
2026-04-13 03:03:53,361 [modules.auxiliary.sysmon] INFO: Uploading sysmon/1776074633.3613281.sysmon.evtx.gz to host
2026-04-13 03:03:53,361 [lib.common.results] INFO: File C:\Sysmon.evtx.gz size is 5691, Max size: 100000000
2026-04-13 03:03:58,341 [modules.auxiliary.evtx] INFO: Collecting logs: Application, HardwareEvents, Internet Explorer, Key Management Service, OAlerts, Security, Setup, System, Windows PowerShell
2026-04-13 03:03:58,560 [lib.common.results] INFO: File 1776074638513671800.HardwareEvents.evtx.gz size is 250, Max size: 100000000
2026-04-13 03:03:58,560 [lib.common.results] INFO: File 1776074638498046800.Application.evtx.gz size is 6888, Max size: 100000000
2026-04-13 03:03:58,576 [lib.common.results] INFO: File 1776074638529296800.InternetExplorer.evtx.gz size is 250, Max size: 100000000
2026-04-13 03:03:58,591 [lib.common.results] INFO: File 1776074638529296800.KeyManagementService.evtx.gz size is 4650, Max size: 100000000
2026-04-13 03:03:58,591 [lib.common.results] INFO: File 1776074638560546800.OAlerts.evtx.gz size is 244, Max size: 100000000
2026-04-13 03:03:58,623 [lib.common.results] INFO: File 1776074638560546800.Security.evtx.gz size is 8093, Max size: 100000000
2026-04-13 03:03:58,623 [lib.common.results] INFO: File 1776074638576171800.Setup.evtx.gz size is 241, Max size: 100000000
2026-04-13 03:03:58,638 [lib.common.results] INFO: File 1776074638591796800.WindowsPowerShell.evtx.gz size is 2058, Max size: 100000000
2026-04-13 03:03:58,654 [lib.common.results] INFO: File 1776074638591796800.System.evtx.gz size is 8075, Max size: 100000000
2026-04-13 03:03:59,150 [modules.auxiliary.fiddler] ERROR: Saz log file not found in guest machine
2026-04-13 03:04:08,371 [modules.auxiliary.sysmon] INFO: Dumping sysmon logs
2026-04-13 03:04:13,430 [modules.auxiliary.sysmon] INFO: Uploading sysmon/1776074653.4306638.sysmon.evtx.gz to host
2026-04-13 03:04:13,438 [lib.common.results] INFO: File C:\Sysmon.evtx.gz size is 5912, Max size: 100000000
2026-04-13 03:04:13,672 [modules.auxiliary.evtx] INFO: Collecting logs: Application, HardwareEvents, Internet Explorer, Key Management Service, OAlerts, Security, Setup, System, Windows PowerShell
2026-04-13 03:04:13,907 [lib.common.results] INFO: File 1776074653844726500.HardwareEvents.evtx.gz size is 250, Max size: 100000000
2026-04-13 03:04:13,907 [lib.common.results] INFO: File 1776074653844726500.InternetExplorer.evtx.gz size is 250, Max size: 100000000
2026-04-13 03:04:13,907 [lib.common.results] INFO: File 1776074653844726500.Application.evtx.gz size is 6888, Max size: 100000000
2026-04-13 03:04:13,922 [lib.common.results] INFO: File 1776074653844726500.KeyManagementService.evtx.gz size is 4650, Max size: 100000000
2026-04-13 03:04:13,954 [lib.common.results] INFO: File 1776074653907226500.OAlerts.evtx.gz size is 244, Max size: 100000000
2026-04-13 03:04:13,986 [lib.common.results] INFO: File 1776074653907226500.Setup.evtx.gz size is 241, Max size: 100000000
2026-04-13 03:04:14,001 [lib.common.results] INFO: File 1776074653907226500.Security.evtx.gz size is 7913, Max size: 100000000
2026-04-13 03:04:14,001 [lib.common.results] INFO: File 1776074653922851500.System.evtx.gz size is 8042, Max size: 100000000
2026-04-13 03:04:14,017 [lib.common.results] INFO: File 1776074653954101500.WindowsPowerShell.evtx.gz size is 2058, Max size: 100000000
2026-04-13 03:04:19,228 [modules.auxiliary.fiddler] ERROR: Saz log file not found in guest machine
2026-04-13 03:04:28,459 [modules.auxiliary.sysmon] INFO: Dumping sysmon logs
2026-04-13 03:04:29,054 [modules.auxiliary.evtx] INFO: Collecting logs: Application, HardwareEvents, Internet Explorer, Key Management Service, OAlerts, Security, Setup, System, Windows PowerShell
2026-04-13 03:04:29,296 [lib.common.results] INFO: File 1776074669242187500.HardwareEvents.evtx.gz size is 250, Max size: 100000000
2026-04-13 03:04:29,304 [lib.common.results] INFO: File 1776074669242187500.Application.evtx.gz size is 6888, Max size: 100000000
2026-04-13 03:04:29,328 [lib.common.results] INFO: File 1776074669242187500.InternetExplorer.evtx.gz size is 250, Max size: 100000000
2026-04-13 03:04:29,343 [lib.common.results] INFO: File 1776074669250000000.KeyManagementService.evtx.gz size is 4650, Max size: 100000000
2026-04-13 03:04:29,367 [lib.common.results] INFO: File 1776074669296875000.OAlerts.evtx.gz size is 244, Max size: 100000000
2026-04-13 03:04:29,375 [lib.common.results] INFO: File 1776074669312500000.Setup.evtx.gz size is 241, Max size: 100000000
2026-04-13 03:04:29,375 [lib.common.results] INFO: File 1776074669312500000.System.evtx.gz size is 8076, Max size: 100000000
2026-04-13 03:04:29,382 [lib.common.results] INFO: File 1776074669304687500.Security.evtx.gz size is 8108, Max size: 100000000
2026-04-13 03:04:29,414 [lib.common.results] INFO: File 1776074669367187500.WindowsPowerShell.evtx.gz size is 2058, Max size: 100000000
2026-04-13 03:04:33,542 [modules.auxiliary.sysmon] INFO: Uploading sysmon/1776074673.5429685.sysmon.evtx.gz to host
2026-04-13 03:04:33,542 [lib.common.results] INFO: File C:\Sysmon.evtx.gz size is 5699, Max size: 100000000
2026-04-13 03:04:39,320 [modules.auxiliary.fiddler] ERROR: Saz log file not found in guest machine
2026-04-13 03:04:42,782 [root] INFO: Analysis timeout hit, terminating analysis
2026-04-13 03:04:42,782 [lib.api.process] INFO: Terminate event set for process 696
2026-04-13 03:04:42,790 [root] DEBUG: 696: Terminate Event: Attempting to dump process 696
2026-04-13 03:04:42,790 [root] DEBUG: 696: VerifyCodeSection: Executable code does not match, 0x64c of 0x154f matching
2026-04-13 03:04:42,790 [root] DEBUG: 696: DoProcessDump: Code modification detected, dumping Imagebase at 0x00900000.
2026-04-13 03:04:42,790 [root] DEBUG: 696: DumpImageInCurrentProcess: Attempting to dump virtual PE image.
2026-04-13 03:04:42,790 [root] DEBUG: 696: DumpProcess: Instantiating PeParser with address: 0x00900000.
2026-04-13 03:04:42,790 [root] DEBUG: 696: DumpProcess: Module entry point VA is 0x000010D4.
2026-04-13 03:04:42,829 [lib.common.results] INFO: File C:\YyIOzAeWhs\CAPE\696_326774241013142026 size is 1915904, Max size: 100000000
2026-04-13 03:04:42,860 [root] DEBUG: 696: DumpProcess: Module image dump success - dump size 0x1d3c00.
2026-04-13 03:04:42,891 [root] INFO: Added new file to list with pid None and path C:\Users\pgabriel\AppData\Local\Temp\Invoice.docx
2026-04-13 03:04:42,891 [root] INFO: Added new file to list with pid None and path C:\Users\pgabriel\AppData\Local\Microsoft\Office\Word15.customUI
2026-04-13 03:04:42,891 [root] INFO: Added new file to list with pid None and path C:\Users\pgabriel\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{7562362D-92E8-4E01-809B-205E26DAE847}.tmp
2026-04-13 03:04:42,891 [lib.api.process] INFO: Termination confirmed for process 696
2026-04-13 03:04:42,891 [root] DEBUG: 696: Terminate Event: monitor shutdown complete for process 696
2026-04-13 03:04:42,891 [root] INFO: Terminate event set for process 696
2026-04-13 03:04:42,891 [root] INFO: Created shutdown mutex
2026-04-13 03:04:43,891 [root] INFO: Shutting down package
2026-04-13 03:04:43,891 [root] INFO: Stopping auxiliary modules
2026-04-13 03:04:43,891 [modules.auxiliary.curtain] ERROR: Curtain - Error collecting PowerShell events - [WinError 6] The handle is invalid
2026-04-13 03:04:43,891 [lib.common.results] INFO: File C:\curtain.log size is 0, Max size: 100000000
2026-04-13 03:04:43,907 [modules.auxiliary.evtx] INFO: Collecting logs: Application, HardwareEvents, Internet Explorer, Key Management Service, OAlerts, Security, Setup, System, Windows PowerShell
2026-04-13 03:04:44,172 [lib.common.results] INFO: File 1776074684110351500.HardwareEvents.evtx.gz size is 250, Max size: 100000000
2026-04-13 03:04:44,197 [lib.common.results] INFO: File 1776074684110351500.Application.evtx.gz size is 6888, Max size: 100000000
2026-04-13 03:04:44,205 [lib.common.results] INFO: File 1776074684125976500.InternetExplorer.evtx.gz size is 250, Max size: 100000000
2026-04-13 03:04:44,212 [lib.common.results] INFO: File 1776074684172851500.OAlerts.evtx.gz size is 244, Max size: 100000000
2026-04-13 03:04:44,220 [lib.common.results] INFO: File 1776074684157226500.KeyManagementService.evtx.gz size is 4650, Max size: 100000000
2026-04-13 03:04:44,267 [lib.common.results] INFO: File 1776074684205078100.Setup.evtx.gz size is 241, Max size: 100000000
2026-04-13 03:04:44,275 [lib.common.results] INFO: File 1776074684197265600.Security.evtx.gz size is 8207, Max size: 100000000
2026-04-13 03:04:44,291 [lib.common.results] INFO: File 1776074684212890600.System.evtx.gz size is 8071, Max size: 100000000
2026-04-13 03:04:44,306 [lib.common.results] INFO: File 1776074684220703100.WindowsPowerShell.evtx.gz size is 2058, Max size: 100000000
2026-04-13 03:04:44,431 [modules.auxiliary.evtx] INFO: Collecting logs: Application, HardwareEvents, Internet Explorer, Key Management Service, OAlerts, Security, Setup, System, Windows PowerShell
2026-04-13 03:04:44,666 [lib.common.results] INFO: File 1776074684612304600.InternetExplorer.evtx.gz size is 250, Max size: 100000000
2026-04-13 03:04:44,682 [lib.common.results] INFO: File 1776074684604492100.HardwareEvents.evtx.gz size is 250, Max size: 100000000
2026-04-13 03:04:44,682 [lib.common.results] INFO: File 1776074684596679600.Application.evtx.gz size is 6888, Max size: 100000000
2026-04-13 03:04:44,690 [lib.common.results] INFO: File 1776074684635742100.KeyManagementService.evtx.gz size is 4650, Max size: 100000000
2026-04-13 03:04:44,721 [lib.common.results] INFO: File 1776074684666992100.OAlerts.evtx.gz size is 244, Max size: 100000000
2026-04-13 03:04:44,729 [lib.common.results] INFO: File 1776074684666992100.Setup.evtx.gz size is 241, Max size: 100000000
2026-04-13 03:04:44,745 [lib.common.results] INFO: File 1776074684666992100.Security.evtx.gz size is 7798, Max size: 100000000
2026-04-13 03:04:44,745 [lib.common.results] INFO: File 1776074684682617100.System.evtx.gz size is 8083, Max size: 100000000
2026-04-13 03:04:44,760 [lib.common.results] INFO: File 1776074684721679600.WindowsPowerShell.evtx.gz size is 2058, Max size: 100000000
2026-04-13 03:04:48,560 [modules.auxiliary.sysmon] INFO: Dumping sysmon logs
2026-04-13 03:04:49,419 [modules.auxiliary.fiddler] ERROR: Saz log file not found in guest machine
2026-04-13 03:04:49,419 [modules.auxiliary.sysmon] INFO: Doing final sysmon log dump
2026-04-13 03:04:53,654 [modules.auxiliary.sysmon] INFO: Uploading sysmon/1776074693.6542969.sysmon.evtx.gz to host
2026-04-13 03:04:53,654 [lib.common.results] INFO: File C:\Sysmon.evtx.gz size is 11659, Max size: 100000000
2026-04-13 03:04:54,482 [modules.auxiliary.sysmon] ERROR: Sysmon log file C:\Sysmon.evtx not found in guest machine
2026-04-13 03:04:54,482 [root] INFO: Finishing auxiliary modules
2026-04-13 03:04:54,482 [root] INFO: Shutting down pipe server and dumping dropped files
2026-04-13 03:04:54,482 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Roaming\Microsoft\Templates\Normal.dotm size is 17789, Max size: 100000000
2026-04-13 03:04:54,482 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Temp\~$nvoice.docx size is 162, Max size: 100000000
2026-04-13 03:04:54,482 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Temp\Invoice.docx size is 18944, Max size: 100000000
2026-04-13 03:04:54,513 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Microsoft\Office\Word15.customUI size is 3514, Max size: 100000000
2026-04-13 03:04:54,529 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{7562362D-92E8-4E01-809B-205E26DAE847}.tmp size is 1024, Max size: 100000000
2026-04-13 03:04:54,544 [root] WARNING: Folder at path "C:\YyIOzAeWhs\debugger" does not exist, skipping
2026-04-13 03:04:54,544 [root] WARNING: Folder at path "C:\YyIOzAeWhs\tlsdump" does not exist, skipping
2026-04-13 03:04:54,544 [root] INFO: Analysis completed
| Name | Label | Manager | Started On | Shutdown On | Route |
|---|---|---|---|---|---|
| win7office2k3flash2800137TWN3H105 | win7office2k3flash2800137TWN3H105 | KVM | 2026-04-13 09:01:57 | 2026-04-13 09:05:06 | internet |
| File Name | Invoice.docx |
|---|---|
| File Size | 18944 bytes |
| File Type | CDFV2 Encrypted |
| MD5 | ba36184d6c6329196e8d3c53c10c5c13 |
| SHA1 | 53c2d2ae15cab446e798bc1d442b361ac8ddd082 |
| SHA256 | e8aebfc820a69624883454d610c70e1a7a7f01811632c8d006d0ebf57af3ccca |
| SHA512 | f70a354642ad8b0af77b84571e9f191ae8a7cc8a6987f7ee54a4994ff1d68897e3546088ff713ae14e6fdb447090ef1cbabd9b90b3ed9bac32bf2110fcdb0045 |
| SHA3-384 | 7adaecd9304efafbbee3a4b01c09a5e0f8fc32e8d0685cd8ccf1057b4040dcf432edc5fc0da6bc5b3c0d83140382c5b8 |
| CRC32 | 55411506 |
| TLSH | T107829E61EF34CF14F2A31FB44E7195257A2DBD99CEA4920A309B730DB1B3D802A22225 |
| Ssdeep | 384:15rZ6tKV8ISXJa+XzzhamAr0l9lADifFCOW1:1WtK+ISXJak8kllfFCj1 |
File
|
| Direct | IP | Country Name |
|---|---|---|
| Y | 8.8.8.8 [VT] | United States |
No domains contacted.
No hosts contacted.
No TCP connections recorded.
No UDP connections recorded.
No domains contacted.
No HTTP(s) requests performed.
No SMTP traffic performed.
No IRC requests performed.
No ICMP traffic performed.
No CIF Results
No Suricata Alerts
No Suricata TLS
No Suricata HTTP